Foxit PDF “Flawed Design” Exploitation
ID: d825acb7-5906-584c-aec6-e49173b38347
STIX ID: report--d825acb7-5906-584c-aec6-e49173b38347
Feed Name: Check Point Research
**Executive Summary:** Check Point Research describes a Foxit Reader-specific PDF exploitation technique that leverages a flawed user prompt workflow to trigger cmd/powershell launches and download remote payloads; the report analyzes multiple active campaigns (including APT-C-35/DoNot Team and criminal actors), details attack chains delivering downloaders, info-stealers, miners and Remcos RAT, documents builders (Python/.NET), provides YARA rules and numerous IOCs, and offers mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
